177
176
def encrypt(self, data, password):
178
177
self.gnupg.passphrase = self.password_encode(password)
179
with open(os.devnull, "w") as devnull:
178
with open(os.devnull) as devnull:
181
180
proc = self.gnupg.run(['--symmetric'],
182
181
create_fhs=['stdin', 'stdout'],
194
193
def decrypt(self, data, password):
195
194
self.gnupg.passphrase = self.password_encode(password)
196
with open(os.devnull, "w") as devnull:
195
with open(os.devnull) as devnull:
198
197
proc = self.gnupg.run(['--decrypt'],
199
198
create_fhs=['stdin', 'stdout'],
200
199
attach_fhs={'stderr': devnull})
201
with contextlib.closing(proc.handles['stdin']) as f:
200
with contextlib.closing(proc.handles['stdin'] ) as f:
203
202
with contextlib.closing(proc.handles['stdout']) as f:
204
203
decrypted_plaintext = f.read()
243
243
server: D-Bus Server
244
244
bus: dbus.SystemBus()
247
246
def __init__(self, interface = avahi.IF_UNSPEC, name = None,
248
247
servicetype = None, port = None, TXT = None,
249
248
domain = "", host = "", max_renames = 32768,
280
278
except dbus.exceptions.DBusException as error:
281
logger.critical("D-Bus Exception", exc_info=error)
279
logger.critical("DBusException: %s", error)
284
282
self.rename_count += 1
286
283
def remove(self):
287
284
"""Derived from the Avahi example code"""
288
285
if self.entry_group_state_changed_match is not None:
313
309
dbus.UInt16(self.port),
314
310
avahi.string_array_to_txt_array(self.TXT))
315
311
self.group.Commit()
317
312
def entry_group_state_changed(self, state, error):
318
313
"""Derived from the Avahi example code"""
319
314
logger.debug("Avahi entry group state change: %i", state)
326
321
elif state == avahi.ENTRY_GROUP_FAILURE:
327
322
logger.critical("Avahi: Error in group state changed %s",
329
raise AvahiGroupError("State changed: {0!s}"
324
raise AvahiGroupError("State changed: %s"
332
326
def cleanup(self):
333
327
"""Derived from the Avahi example code"""
334
328
if self.group is not None:
340
334
self.group = None
343
336
def server_state_changed(self, state, error=None):
344
337
"""Derived from the Avahi example code"""
345
338
logger.debug("Avahi server state change: %i", state)
364
357
logger.debug("Unknown state: %r", state)
366
359
logger.debug("Unknown state: %r: %r", state, error)
368
360
def activate(self):
369
361
"""Derived from the Avahi example code"""
370
362
if self.server is None:
382
374
"""Add the new name to the syslog messages"""
383
375
ret = AvahiService.rename(self)
384
376
syslogger.setFormatter(logging.Formatter
385
('Mandos ({0}) [%(process)d]:'
386
' %(levelname)s: %(message)s'
377
('Mandos (%s) [%%(process)d]:'
378
' %%(levelname)s: %%(message)s'
390
382
def timedelta_to_milliseconds(td):
496
488
"rb") as secfile:
497
489
client["secret"] = secfile.read()
499
raise TypeError("No secret or secfile for section {0}"
491
raise TypeError("No secret or secfile for section %s"
501
493
client["timeout"] = string_to_delta(section["timeout"])
502
494
client["extended_timeout"] = string_to_delta(
503
495
section["extended_timeout"])
512
504
client["last_checker_status"] = -2
516
509
def __init__(self, settings, name = None):
510
"""Note: the 'checker' key in 'config' sets the
511
'checker_command' attribute and *not* the 'checker'
518
514
# adding all client settings
519
515
for setting, value in settings.iteritems():
536
532
logger.debug(" Fingerprint: %s", self.fingerprint)
537
533
self.created = settings.get("created",
538
534
datetime.datetime.utcnow())
540
536
# attributes specific for this server instance
541
537
self.checker = None
542
538
self.checker_initiator_tag = None
697
693
command = self.checker_command % escaped_attrs
698
694
except TypeError as error:
699
logger.error('Could not format string "%s"',
700
self.checker_command, exc_info=error)
695
logger.error('Could not format string "%s":'
696
' %s', self.checker_command, error)
701
697
return True # Try again later
702
698
self.current_checker_command = command
721
717
gobject.source_remove(self.checker_callback_tag)
722
718
self.checker_callback(pid, status, command)
723
719
except OSError as error:
724
logger.error("Failed to start subprocess",
720
logger.error("Failed to start subprocess: %s",
726
722
# Re-run this periodically if run by gobject.timeout_add
736
732
logger.debug("Stopping checker for %(name)s", vars(self))
738
self.checker.terminate()
734
os.kill(self.checker.pid, signal.SIGTERM)
740
736
#if self.checker.poll() is None:
741
# self.checker.kill()
737
# os.kill(self.checker.pid, signal.SIGKILL)
742
738
except OSError as error:
743
739
if error.errno != errno.ESRCH: # No such process
761
757
# "Set" method, so we fail early here:
762
758
if byte_arrays and signature != "ay":
763
759
raise ValueError("Byte arrays not supported for non-'ay'"
764
" signature {0!r}".format(signature))
760
" signature %r" % signature)
765
761
def decorator(func):
766
762
func._dbus_is_property = True
767
763
func._dbus_interface = dbus_interface
778
def dbus_interface_annotations(dbus_interface):
779
"""Decorator for marking functions returning interface annotations
783
@dbus_interface_annotations("org.example.Interface")
784
def _foo(self): # Function name does not matter
785
return {"org.freedesktop.DBus.Deprecated": "true",
786
"org.freedesktop.DBus.Property.EmitsChangedSignal":
790
func._dbus_is_interface = True
791
func._dbus_interface = dbus_interface
792
func._dbus_name = dbus_interface
797
def dbus_annotations(annotations):
798
"""Decorator to annotate D-Bus methods, signals or properties
801
@dbus_service_property("org.example.Interface", signature="b",
803
@dbus_annotations({{"org.freedesktop.DBus.Deprecated": "true",
804
"org.freedesktop.DBus.Property."
805
"EmitsChangedSignal": "false"})
806
def Property_dbus_property(self):
807
return dbus.Boolean(False)
810
func._dbus_annotations = annotations
815
774
class DBusPropertyException(dbus.exceptions.DBusException):
816
775
"""A base class for D-Bus property-related exceptions
843
def _is_dbus_thing(thing):
844
"""Returns a function testing if an attribute is a D-Bus thing
846
If called like _is_dbus_thing("method") it returns a function
847
suitable for use as predicate to inspect.getmembers().
849
return lambda obj: getattr(obj, "_dbus_is_{0}".format(thing),
802
def _is_dbus_property(obj):
803
return getattr(obj, "_dbus_is_property", False)
852
def _get_all_dbus_things(self, thing):
805
def _get_all_dbus_properties(self):
853
806
"""Returns a generator of (name, attribute) pairs
855
return ((getattr(athing.__get__(self), "_dbus_name",
857
athing.__get__(self))
808
return ((prop.__get__(self)._dbus_name, prop.__get__(self))
858
809
for cls in self.__class__.__mro__
860
inspect.getmembers(cls,
861
self._is_dbus_thing(thing)))
811
inspect.getmembers(cls, self._is_dbus_property))
863
813
def _get_dbus_property(self, interface_name, property_name):
864
814
"""Returns a bound method if one exists which is a D-Bus
867
817
for cls in self.__class__.__mro__:
868
818
for name, value in (inspect.getmembers
870
self._is_dbus_thing("property"))):
819
(cls, self._is_dbus_property)):
871
820
if (value._dbus_name == property_name
872
821
and value._dbus_interface == interface_name):
873
822
return value.__get__(self)
915
864
Note: Will not include properties with access="write".
918
for name, prop in self._get_all_dbus_things("property"):
867
for name, prop in self._get_all_dbus_properties():
919
868
if (interface_name
920
869
and interface_name != prop._dbus_interface):
921
870
# Interface non-empty but did not match
936
885
path_keyword='object_path',
937
886
connection_keyword='connection')
938
887
def Introspect(self, object_path, connection):
939
"""Overloading of standard D-Bus method.
941
Inserts property tags and interface annotation tags.
888
"""Standard D-Bus method, overloaded to insert property tags.
943
890
xmlstring = dbus.service.Object.Introspect(self, object_path,
951
898
e.setAttribute("access", prop._dbus_access)
953
900
for if_tag in document.getElementsByTagName("interface"):
955
901
for tag in (make_tag(document, name, prop)
957
in self._get_all_dbus_things("property")
903
in self._get_all_dbus_properties()
958
904
if prop._dbus_interface
959
905
== if_tag.getAttribute("name")):
960
906
if_tag.appendChild(tag)
961
# Add annotation tags
962
for typ in ("method", "signal", "property"):
963
for tag in if_tag.getElementsByTagName(typ):
965
for name, prop in (self.
966
_get_all_dbus_things(typ)):
967
if (name == tag.getAttribute("name")
968
and prop._dbus_interface
969
== if_tag.getAttribute("name")):
970
annots.update(getattr
974
for name, value in annots.iteritems():
975
ann_tag = document.createElement(
977
ann_tag.setAttribute("name", name)
978
ann_tag.setAttribute("value", value)
979
tag.appendChild(ann_tag)
980
# Add interface annotation tags
981
for annotation, value in dict(
983
*(annotations().iteritems()
984
for name, annotations in
985
self._get_all_dbus_things("interface")
986
if name == if_tag.getAttribute("name")
988
ann_tag = document.createElement("annotation")
989
ann_tag.setAttribute("name", annotation)
990
ann_tag.setAttribute("value", value)
991
if_tag.appendChild(ann_tag)
992
907
# Add the names to the return values for the
993
908
# "org.freedesktop.DBus.Properties" methods
994
909
if (if_tag.getAttribute("name")
1009
924
except (AttributeError, xml.dom.DOMException,
1010
925
xml.parsers.expat.ExpatError) as error:
1011
926
logger.error("Failed to override Introspection method",
1013
928
return xmlstring
1029
944
def __new__(mcs, name, bases, attr):
1030
945
# Go through all the base classes which could have D-Bus
1031
946
# methods, signals, or properties in them
1032
old_interface_names = []
1033
947
for base in (b for b in bases
1034
948
if issubclass(b, dbus.service.Object)):
1035
949
# Go though all attributes of the base class
1045
959
alt_interface = (attribute._dbus_interface
1046
960
.replace("se.recompile.Mandos",
1047
961
"se.bsnet.fukt.Mandos"))
1048
if alt_interface != attribute._dbus_interface:
1049
old_interface_names.append(alt_interface)
1050
962
# Is this a D-Bus signal?
1051
963
if getattr(attribute, "_dbus_is_signal", False):
1052
964
# Extract the original non-method function by
1067
979
nonmethod_func.func_name,
1068
980
nonmethod_func.func_defaults,
1069
981
nonmethod_func.func_closure)))
1070
# Copy annotations, if any
1072
new_function._dbus_annotations = (
1073
dict(attribute._dbus_annotations))
1074
except AttributeError:
1076
982
# Define a creator of a function to call both the
1077
983
# old and new functions, so both the old and new
1078
984
# signals gets sent when the function is called
1106
1012
attribute.func_name,
1107
1013
attribute.func_defaults,
1108
1014
attribute.func_closure)))
1109
# Copy annotations, if any
1111
attr[attrname]._dbus_annotations = (
1112
dict(attribute._dbus_annotations))
1113
except AttributeError:
1115
1015
# Is this a D-Bus property?
1116
1016
elif getattr(attribute, "_dbus_is_property", False):
1117
1017
# Create a new, but exactly alike, function
1131
1031
attribute.func_name,
1132
1032
attribute.func_defaults,
1133
1033
attribute.func_closure)))
1134
# Copy annotations, if any
1136
attr[attrname]._dbus_annotations = (
1137
dict(attribute._dbus_annotations))
1138
except AttributeError:
1140
# Is this a D-Bus interface?
1141
elif getattr(attribute, "_dbus_is_interface", False):
1142
# Create a new, but exactly alike, function
1143
# object. Decorate it to be a new D-Bus interface
1144
# with the alternate D-Bus interface name. Add it
1146
attr[attrname] = (dbus_interface_annotations
1149
(attribute.func_code,
1150
attribute.func_globals,
1151
attribute.func_name,
1152
attribute.func_defaults,
1153
attribute.func_closure)))
1154
# Deprecate all old interfaces
1155
iname="_AlternateDBusNamesMetaclass_interface_annotation{0}"
1156
for old_interface_name in old_interface_names:
1157
@dbus_interface_annotations(old_interface_name)
1159
return { "org.freedesktop.DBus.Deprecated": "true" }
1160
# Find an unused name
1161
for aname in (iname.format(i) for i in itertools.count()):
1162
if aname not in attr:
1165
1034
return type.__new__(mcs, name, bases, attr)
1190
1059
("/clients/" + client_object_name))
1191
1060
DBusObjectWithProperties.__init__(self, self.bus,
1192
1061
self.dbus_object_path)
1194
1063
def notifychangeproperty(transform_func,
1195
1064
dbus_name, type_func=lambda x: x,
1196
1065
variant_level=1):
1220
1089
return property(lambda self: getattr(self, attrname), setter)
1222
1092
expires = notifychangeproperty(datetime_to_dbus, "Expires")
1223
1093
approvals_pending = notifychangeproperty(dbus.Boolean,
1224
1094
"ApprovalPending",
1312
1182
(self.approval_duration),
1313
1183
self._reset_approved)
1315
1186
## D-Bus methods, signals & properties
1316
1187
_interface = "se.recompile.Mandos.Client"
1320
@dbus_interface_annotations(_interface)
1322
return { "org.freedesktop.DBus.Property.EmitsChangedSignal":
1327
1191
# CheckerCompleted - signal
1742
1606
sent = session.send(client.secret[sent_size:])
1743
1607
except gnutls.errors.GNUTLSError as error:
1744
logger.warning("gnutls send failed",
1608
logger.warning("gnutls send failed")
1747
1610
logger.debug("Sent: %d, remaining: %d",
1748
1611
sent, len(client.secret)
1764
1627
except gnutls.errors.GNUTLSError as error:
1765
logger.warning("GnuTLS bye failed",
1628
logger.warning("GnuTLS bye failed")
1769
1631
def peer_certificate(session):
2081
1943
elif suffix == "w":
2082
1944
delta = datetime.timedelta(0, 0, 0, 0, 0, 0, value)
2084
raise ValueError("Unknown suffix {0!r}"
1946
raise ValueError("Unknown suffix %r" % suffix)
2086
1947
except (ValueError, IndexError) as e:
2087
1948
raise ValueError(*(e.args))
2088
1949
timevalue += delta
2103
1964
if not noclose:
2104
1965
# Close all standard open file descriptors
2105
null = os.open(os.devnull, os.O_NOCTTY | os.O_RDWR)
1966
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
2106
1967
if not stat.S_ISCHR(os.fstat(null).st_mode):
2107
1968
raise OSError(errno.ENODEV,
2108
"{0} not a character device"
2109
.format(os.devnull))
1969
"%s not a character device"
2110
1971
os.dup2(null, sys.stdin.fileno())
2111
1972
os.dup2(null, sys.stdout.fileno())
2112
1973
os.dup2(null, sys.stderr.fileno())
2122
1983
parser = argparse.ArgumentParser()
2123
1984
parser.add_argument("-v", "--version", action="version",
2124
version = "%(prog)s {0}".format(version),
1985
version = "%%(prog)s %s" % version,
2125
1986
help="show version number and exit")
2126
1987
parser.add_argument("-i", "--interface", metavar="IF",
2127
1988
help="Bind to interface IF")
2231
2092
if server_settings["servicename"] != "Mandos":
2232
2093
syslogger.setFormatter(logging.Formatter
2233
('Mandos ({0}) [%(process)d]:'
2234
' %(levelname)s: %(message)s'
2235
.format(server_settings
2094
('Mandos (%s) [%%(process)d]:'
2095
' %%(levelname)s: %%(message)s'
2096
% server_settings["servicename"]))
2238
2098
# Parse config file with clients
2239
2099
client_config = configparser.SafeConfigParser(Client
2257
2117
pidfilename = "/var/run/mandos.pid"
2259
2119
pidfile = open(pidfilename, "w")
2260
except IOError as e:
2261
logger.error("Could not open file %r", pidfilename,
2121
logger.error("Could not open file %r", pidfilename)
2264
for name in ("_mandos", "mandos", "nobody"):
2124
uid = pwd.getpwnam("_mandos").pw_uid
2125
gid = pwd.getpwnam("_mandos").pw_gid
2266
uid = pwd.getpwnam(name).pw_uid
2267
gid = pwd.getpwnam(name).pw_gid
2128
uid = pwd.getpwnam("mandos").pw_uid
2129
gid = pwd.getpwnam("mandos").pw_gid
2269
2130
except KeyError:
2132
uid = pwd.getpwnam("nobody").pw_uid
2133
gid = pwd.getpwnam("nobody").pw_gid
2293
2156
.gnutls_global_set_log_function(debug_gnutls))
2295
2158
# Redirect stdin so all checkers get /dev/null
2296
null = os.open(os.devnull, os.O_NOCTTY | os.O_RDWR)
2159
null = os.open(os.path.devnull, os.O_NOCTTY | os.O_RDWR)
2297
2160
os.dup2(null, sys.stdin.fileno())
2308
2171
global main_loop
2309
2172
# From the Avahi example code
2310
DBusGMainLoop(set_as_default=True)
2173
DBusGMainLoop(set_as_default=True )
2311
2174
main_loop = gobject.MainLoop()
2312
2175
bus = dbus.SystemBus()
2313
2176
# End of Avahi example code
2319
2182
("se.bsnet.fukt.Mandos", bus,
2320
2183
do_not_queue=True))
2321
2184
except dbus.exceptions.NameExistsException as e:
2322
logger.error("Disabling D-Bus:", exc_info=e)
2185
logger.error(unicode(e) + ", disabling D-Bus")
2323
2186
use_dbus = False
2324
2187
server_settings["use_dbus"] = False
2325
2188
tcp_server.use_dbus = False
2352
2215
(stored_state))
2353
2216
os.remove(stored_state_path)
2354
2217
except IOError as e:
2355
if e.errno == errno.ENOENT:
2356
logger.warning("Could not load persistent state: {0}"
2357
.format(os.strerror(e.errno)))
2359
logger.critical("Could not load persistent state:",
2218
logger.warning("Could not load persistent state: {0}"
2220
if e.errno != errno.ENOENT:
2362
2222
except EOFError as e:
2363
2223
logger.warning("Could not load persistent state: "
2364
"EOFError:", exc_info=e)
2224
"EOFError: {0}".format(e))
2366
2226
with PGPEngine() as pgp:
2367
2227
for client_name, client in clients_data.iteritems():
2428
2289
for client_name in (set(client_settings)
2429
2290
- set(old_client_settings)):
2430
2291
clients_data[client_name] = client_settings[client_name]
2432
2293
# Create all client objects
2433
2294
for client_name, client in clients_data.iteritems():
2434
2295
tcp_server.clients[client_name] = client_class(
2456
2317
signal.signal(signal.SIGTERM, lambda signum, frame: sys.exit())
2459
class MandosDBusService(DBusObjectWithProperties):
2320
class MandosDBusService(dbus.service.Object):
2460
2321
"""A D-Bus proxy object"""
2461
2322
def __init__(self):
2462
2323
dbus.service.Object.__init__(self, bus, "/")
2463
2324
_interface = "se.recompile.Mandos"
2465
@dbus_interface_annotations(_interface)
2467
return { "org.freedesktop.DBus.Property"
2468
".EmitsChangedSignal":
2471
2326
@dbus.service.signal(_interface, signature="o")
2472
2327
def ClientAdded(self, objpath):
2564
2419
pickle.dump((clients, client_settings), stored_state)
2565
2420
os.rename(tempname, stored_state_path)
2566
2421
except (IOError, OSError) as e:
2422
logger.warning("Could not save persistent state: {0}"
2569
2426
os.remove(tempname)
2570
2427
except NameError:
2572
if e.errno in (errno.ENOENT, errno.EACCES, errno.EEXIST):
2573
logger.warning("Could not save persistent state: {0}"
2574
.format(os.strerror(e.errno)))
2576
logger.warning("Could not save persistent state:",
2429
if e.errno not in set((errno.ENOENT, errno.EACCES,
2580
2433
# Delete all clients, and settings from config
2608
2461
service.port = tcp_server.socket.getsockname()[1]
2610
2463
logger.info("Now listening on address %r, port %d,"
2611
" flowinfo %d, scope_id %d",
2612
*tcp_server.socket.getsockname())
2464
" flowinfo %d, scope_id %d"
2465
% tcp_server.socket.getsockname())
2614
logger.info("Now listening on address %r, port %d",
2615
*tcp_server.socket.getsockname())
2467
logger.info("Now listening on address %r, port %d"
2468
% tcp_server.socket.getsockname())
2617
2470
#service.interface = tcp_server.socket.getsockname()[3]
2622
2475
service.activate()
2623
2476
except dbus.exceptions.DBusException as error:
2624
logger.critical("D-Bus Exception", exc_info=error)
2477
logger.critical("DBusException: %s", error)
2627
2480
# End of Avahi example code
2634
2487
logger.debug("Starting main loop")
2635
2488
main_loop.run()
2636
2489
except AvahiError as error:
2637
logger.critical("Avahi Error", exc_info=error)
2490
logger.critical("AvahiError: %s", error)
2640
2493
except KeyboardInterrupt: